The file with MD5 b140a84d99f6af63664c36079857265e contains executable code.
It puts strings on the stack such as "---.exe", C:\TEMP\TrustedInstaller.exe and a domain name which redirected to other URLs from which encrypted binary files could be downloaded (April 2013).

Filename: zdw.decrypted
Filesize: 359936
MD5: 1edef5be09486d8658f3f547b0fb2e0e
SHA1: 7ca33ed80b9d28ee075364f302ec608406079239
SHA256: e5b875d462fbd6217c905f7ef7d472645c4b32bf10efbef82d4f3af8f47182ee
The executable created the following file:
Filename: C:\Documents and Settings\%USERNAME%\Local Settings\Temp\_install_\msiexec.exe
Filesize: 250880
MD5: 88d67dcabe60bdcf5e225765ceadbd09
SHA1: 5ac7641edc14dee9e28f783da5cef53f4c1cb18a
SHA256: 092d2e51eeb2aa092dbf35571dd4218877c2b25677299a6c71b60ef2bf5a7ca5
The executable file with MD5 88d67dcabe60bdcf5e225765ceadbd09 was executed after which it listened on TCP port 8000.
The executable file with MD5 1edef5be09486d8658f3f547b0fb2e0e changed its file attributes to set the system and hidden attributes.

"Windows Security Alert
To help protect your computer, Windows Firewall has blocked some features of this program.
Do you want to keep blocking this program?
Name: Marko
Publisher: House
Keep Blocking Unblock Ask Me Later
Windows Firewall has blocked this program from accepting connections from the Internet or a network. If you recognize the program or trust the publisher you can unblock it. When should I unblock a program?"

Filename: zin.decrypted
Filesize: 771584
MD5: 0f8d239dc9c43c839c1820e171b43603
SHA1: 7457bc8c52f2e01e369812562f01699ef4caeecd
SHA256: 01ae2b3011dbef145b63bf574054bd1a4b569fe0dd7349aba60d29c30cf7db69
The executable created the following file:
Filename: C:\Documents and Settings\%USERNAME%\Local Settings\Temp\_install_\msiexec.exe
Filesize: 97280
MD5: 091999351f12b922b46b9f123852a6a8
SHA1: 34b73c5b8389c96bd7f180f674b531971296dbf9
SHA256: 970442897bec2c32e69aa9a89fb2fb1406aec897a568e0ebc2767afc414bcec0
The file with MD5 091999351f12b922b46b9f123852a6a8 was executed.
The executable file with MD5 0f8d239dc9c43c839c1820e171b43603 changed its file attributes to set the system and hidden attributes.

On 16th of April 2013 the domain name in the binary file with MD5 b140a84d99f6af63664c36079857265e did not resolve to an IP address for some time. After that, it redirected to 217.23.11.124 from which weakly encrypted binaries could be downloaded.

Filename: zzz.decrypted
Filesize: 214016
MD5: cee33e59343ed51102057c62d36d4512
SHA1: 6197717ad1594d5ecd1162541f57ca7245f11aa3
SHA256: 070e726889e9da57bcbfe1ab4e4d2bf277dc5b98a21bc3c066cb5a9bbcf0351a
The file with MD5 cee33e59343ed51102057c62d36d4512 was packed with UPX, when it is decompressed the file has a filesize of 1791488 bytes and the following checksums:
MD5: 42a51a220501e38b5b93306ff206600b
SHA1: cc8bbfb4622e99a2b94e59698b527c8881e2466e
SHA256: 9fcda4fb993424fb035b1600fab8e8c6f56e33c4174b11b55aa311650b0cbf5f
The executable created the following file:
Filename: C:\Documents and Settings\%USERNAME%\Local Settings\Temp\_install_\msiexec.exe
Filesize: 97280
MD5: 091999351f12b922b46b9f123852a6a8
SHA1: 34b73c5b8389c96bd7f180f674b531971296dbf9
SHA256: 970442897bec2c32e69aa9a89fb2fb1406aec897a568e0ebc2767afc414bcec0
The file with MD5 091999351f12b922b46b9f123852a6a8 was executed.
The executable file with MD5 42a51a220501e38b5b93306ff206600b changed its file attributes to set the system and hidden attributes.

Filename: zzz.decrypted
Filesize: 214016
MD5: e4f4ae24234743e3cf9b8483a06ad2bd
SHA1: 665687965cb2bb78a3ca984b8a77f630ff838a8c
SHA256: cc1400691183db98de8e4ab8162a8d42802e178a3190a816407b2dea5ec6018d
The file with MD5 e4f4ae24234743e3cf9b8483a06ad2bd was packed with UPX, when it is decompressed the file has a filesize of 1666048 bytes and the following checksums:
MD5: cd9282ddf6331fd71674b92575932ba0
SHA1: 23525f9074d1031ddd1d71180bc12e48be6a0971
SHA256: b26431576bdc0d52e8005983bf2f3b9120f6ca99226a942bbe701fc2596b8c45

On and after 20th of April 2013 the domain name in the binary file with MD5 b140a84d99f6af63664c36079857265e did not resolve to an IP address.